CVE-2019-1491High
Microsoft SharePoint Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
CVE-2019-1491 · pending
📋 Description
An information disclosure vulnerability exists in SharePoint Server. An attacker who exploited this vulnerability could read arbitrary files on the server. To exploit the vulnerability, an attacker would need to send a specially crafted request to a susceptible SharePoint Server instance. The update addresses the vulnerability by changing how affected APIs process requests.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4484143 (Security Update) KB4484142 (Security Update) KB4484165 (Security Update) KB4484157 (Security Update)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1491
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e67a00b1-7fd8-4f3b-abef-89cdcde23e9f
- patchhttps://www.microsoft.com/download/details.aspx?familyid=fe4f85af-6da2-4c91-8be4-51d245dc70a8
- patchhttps://www.microsoft.com/download/details.aspx?familyid=f96cfc07-5a2a-41cf-ae9c-ec049c18e11b
- patchhttps://www.microsoft.com/download/details.aspx?familyid=8c214a20-166f-4d37-9de0-633f8d2441fc